Friday, April 26, 2024

Cyber security firm claims data of 2.5 billion Google Chrome users at risk

Google Chrome is a web browser used by netizens from across the world. A latest cyber security firm claims to have detected a vulnerability in Google Chrome and Chromium-based browsers which puts data of over 2.5 billion users at risk.

In its blog post, the cyber security firm named Imperva Red has revealed that the vulnerability labelled as ‘CVE-2022-365’, which allows the the theft of sensitive files like crypto wallets and cloud provider credentials.

The blog points to a type of file called ‘Symlink’, which points to another file or directory. This file also allows the operating system to treat the linked file or directory as it was its location.

The blog states that these symlinks can introduce vulnerabilities if not handled properly. The browser did not check if the symlink was directing at a location which was not intended to be accessible, allowing the theft of sensitive files.

Imperva Red has warned that an attacker could design a fake website posing to offer a crypto wallet service. This fake website can con the user into creating a new wallet on pretext of asking them to download ‘recovery keys’.

According to the blog, the keys are nothing but a zip file comprising symlink to a sensitive file or folder on the users’ computer. The website could be designed in such a way that it looks legitimate and the process of uploading and downloading the ‘recovery keys’ could seem normal.

Several crypto wallets and other services usually ask users to download recovery keys to access their accounts, which are a backup in case the user loses access to account. But an attacker can misuse this by handing out a zip file containing a symlink to the user instead of an actual recovery keys. If uploaded, the attacker can access the sensitive files on the user’s computer by processing the symlink.

The hackers target individuals and organisations holding crypto currencies as these digital assets can be highly valuable. The blog suggests keeping software up to date and not downloading files from malicious sources.

 

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Stay Connected

2,141,679FansLike
44,516FollowersFollow
567,000SubscribersSubscribe

Public Poll

Which political party do you believe is best suited to address the unique challenges facing Jammu and Kashmir?
×

Latest Articles

Time On air Program Name
6.00 a.m Ravi Shankar  yoga guru, a spiritual leader
6:30 a.m Guru Bani
7:00 a.m Paigam E Noor   
7:30 a.m News center
7:30 a.m Punjabi news
8:30 a.m Salam Jammu Kashmir  
11:00 a.m National News Hindi
11:30 a.m Urdu khabar Nama
12:00 p.m Hindu news ( National )
12:30 p.m Hindi news (Jammu Kashmir  )
1:00 p.m Debate with Sanam
2:30 p.m Urdu khabar National
3:30 p.m Jammu Kashmir News
4:00 p.m Special report from Srinagar
4:30 p.m Kashmire News
5:00 p.m 5 ka punch
5:40 p.m Ground report from JK
6:00 p.m 6PM News  Urdu
6:30 p.m Ladakh special
7:00 p.m Kashmir News
7:30 p.m News Centre
7:30 p.m News Centre
8:00 p.m Urdu khabar namaJKspecial
8:30 p.m Mahasangram Debate show
9:00 p.m Kashmir e news
9:30 p.m ABB TAK 
10:30 p.m Hindi news National
11:00 p.m Dogri News
11:30 p.m National update